HomeSecurityAlarming rise in ClickFix attacks via Malvertising "DeceptionAds"

Alarming rise in ClickFix attacks via Malvertising “DeceptionAds”

Cybersecurity experts have revealed a worrying development in ClickFix-type attacks, which exploit an advertising network through malvertising campaigns, known as DeceptionAds .

DeceptionAds

The malicious “DeceptionAds” campaign generates over 1 million ad impressions daily, resulting in thousands of users falling victim, losing accounts and money through more than 3,000 websites that direct traffic to malicious pages.

Read more: Hackers exploit Google Search ads to spread Malvertising

The attacks primarily target users of pirated movie websites, redirecting them to deceptive CAPTCHA. There, users are tricked into executing PowerShell, which lead to the installation of malware, such as the Lumma. What makes this threat even more worrisome is that it is not limited to a single actor. Multiple threat clusters are leveraging the same method to spread malware, including trojans, stealers, and high-risk frameworks, such as Brute Ratel C4.

See also: “Konfety”: Malicious ads exploit 250+ Google Play apps

The campaign is linked to the Monetag platform, which offers advertising services, while the malicious actors use tools like BeMob to cover their tracks. In response, Monetag has disabled more than 200 accounts associated with the campaign, while BeMob has made similar deletions. Nevertheless, the malicious actions continued until December 2024.

malicious ads

This campaign highlights the urgent need for stricter account verification and better content management on ad networks. It also highlights how platforms designed for legitimate purposes can become tools for malicious activity.

Read more: Malicious League of Legends ads spread info-stealer malware

The responsibility for preventing such attacks falls not only on ad networks, but also on publishers, ad analytics services, and hosting providers, who often neglect to take effective measures.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS